Google routes return 500 on a missing OAuth state or a missing or partial JSON body #56

Open
opened 2026-10-03 19:44:41 +00:00 by jalenluorion · 0 comments
Member

What's wrong

  • GET /api/google/oauth/callback reads session["state"] (L78) with no guard. Hitting the callback without going through /api/google/authorize first (expired cookie, second tab, bookmark) raises KeyError, so 500.
  • POST /api/google/calendar/events/add (L134-172): no body gives 500 (Flask's 415 is swallowed by except Exception). data["start"], data["end"], data["title"] and data["local_event_id"] are never validated, and local_event_id is read only after add_event() has already created the event in Google, so a body without it leaves an orphan event in the user's Google Calendar and still returns 500.
  • POST /api/google/calendar/events/bulk (L125-131): request.get_json().get(...) raises AttributeError for a null body, so 500.

The DELETE route takes no body and is fine.

How to reproduce

curl -i 'http://localhost:5001/api/google/oauth/callback?code=x&state=y'
curl -i -X POST $API/api/google/calendar/events/add -H "Authorization: Bearer $TOKEN"
curl -i -X POST $API/api/google/calendar/events/bulk -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' -d 'null'

In tests, mocker.patch("app.api.google.fetch_user_credentials", return_value={"token": "t"}), and also mock add_event and give the user a calendar_id.

Expected

  • Callback without a stored state: 400 or a redirect to the frontend with an error, never 500.
  • add and bulk: 400 naming the missing fields, checked before any Google API call.

Where to look

  • api/app/api/google.py: oauth2callback() L75-87, bulk_events() L125-131, add_event_route() L134-172.
  • api/app/utils/date.py convert_to_iso8601() (raises ValueError on any other date format).
  • Line numbers are from main at 2c5f2e9.

Done when

  • the three cases return 4xx with a clear message, and no Google call is made for an invalid add body
  • tests in api/tests/api/test_google_validation.py
**What's wrong** - `GET /api/google/oauth/callback` reads `session["state"]` (L78) with no guard. Hitting the callback without going through `/api/google/authorize` first (expired cookie, second tab, bookmark) raises KeyError, so 500. - `POST /api/google/calendar/events/add` (L134-172): no body gives 500 (Flask's 415 is swallowed by `except Exception`). `data["start"]`, `data["end"]`, `data["title"]` and `data["local_event_id"]` are never validated, and `local_event_id` is read only after `add_event()` has already created the event in Google, so a body without it leaves an orphan event in the user's Google Calendar and still returns 500. - `POST /api/google/calendar/events/bulk` (L125-131): `request.get_json().get(...)` raises AttributeError for a `null` body, so 500. The DELETE route takes no body and is fine. **How to reproduce** ``` curl -i 'http://localhost:5001/api/google/oauth/callback?code=x&state=y' curl -i -X POST $API/api/google/calendar/events/add -H "Authorization: Bearer $TOKEN" curl -i -X POST $API/api/google/calendar/events/bulk -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' -d 'null' ``` In tests, `mocker.patch("app.api.google.fetch_user_credentials", return_value={"token": "t"})`, and also mock `add_event` and give the user a `calendar_id`. **Expected** - Callback without a stored state: 400 or a redirect to the frontend with an error, never 500. - add and bulk: 400 naming the missing fields, checked before any Google API call. **Where to look** - `api/app/api/google.py`: `oauth2callback()` L75-87, `bulk_events()` L125-131, `add_event_route()` L134-172. - `api/app/utils/date.py` `convert_to_iso8601()` (raises ValueError on any other date format). - Line numbers are from main at 2c5f2e9. **Done when** - [ ] the three cases return 4xx with a clear message, and no Google call is made for an invalid add body - [ ] tests in `api/tests/api/test_google_validation.py`
jalenluorion added this to the Phase 1 milestone 2026-10-03 19:44:41 +00:00
jalenluorion added this to the CMUCal project 2026-10-03 19:45:09 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ScottyLabs/cal#56
No description provided.